Security Architect
Brak informacji o wynagrodzeniu
SeniorFull-time
#425193·Dodano 2 dni temu·0
Źródło: Capital.comTech Stack / Keywords
SecurityArchitecture
Firma i stanowisko
Capital.com is a global fintech company with over 1,000,000 clients worldwide. Their platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology helping traders make better decisions. The company operates across five regulated jurisdictions.
Wymagania
- 8+ years in security focusing on GRC, regulatory compliance, and risk management at enterprise level.
- Proven experience designing enterprise security architectures or frameworks; experience in regulated financial services preferred.
- Deep command of ISO 27001 and PCI-DSS; working knowledge of DORA and NIS2 preferred.
- Multi-jurisdiction compliance experience, especially with FCA or CySEC.
- Ability to advise and influence C-suite stakeholders on complex security and regulatory issues.
- Structured, analytical thinking able to manage multiple regulatory regimes with precision.
- Fluent English, written and spoken.
Nice to have:
- Experience managing regulatory submissions or engaging with FCA, CySEC, ASIC, SCB, or SCA.
- TPRM design experience including DORA ICT third-party risk requirements.
- Business Continuity Management experience with operational resilience and Board presentations.
- Security awareness program design with measurable outcomes.
- Experience building or scaling a Corporate Security function.
- Professional certifications such as CISSP, CISM, or CRISC.
Obowiązki
- Own the enterprise security GRC framework including policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
- Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and prioritize remediation.
- Act as final authority on regulatory interpretation for security, including audit and submission documentation.
- Manage compliance and obligation frameworks across FCA, CySEC, ASIC, SCB, and SCA jurisdictions, including horizon scanning.
- Represent the company in regulatory discussions alongside the CISO and General Counsel.
- Define the company's human-risk philosophy and design the security awareness architecture.
- Advise senior leadership on security risk, regulatory obligations, and investment trade-offs.
- Define architectural standards for the Corporate Security team and approve significant framework changes.
- Support Third-Party Risk Management and Business Continuity & Crisis Management from security and technical perspectives.
Benefity
- Competitive salary.
- Work-life harmony with hybrid work model.
- Generous annual leave policy.
- Employee referral program.
- Comprehensive health and pension benefits.
- 30 additional remote work days yearly (some restrictions apply).
- Two additional paid volunteer days per year.
Płatny urlop
Opieka zdrowotna
Capital.com
8 aktywnych ofert